4 ms·
> gsub(/\/\.\./, "/", request_filename) # avoid directory trasversal Hmmmm http://localhost:8888/..../..../..../..../..../..../.../..../etc/passwd http://loca
by hackideiomat 3y ago
> gsub(/\/\.\./, "/", request_filename) # avoid directory trasversal
Hmmmm
http://localhost:8888/..../..../..../..../..../..../.../..../etc/passwd http://localhost:8888/..../..../..../..../..../..../.../.......
- tmsbrg 3y agodamn, you beat me to it. Was gonna write: http://localhost:8888/..../..../..../..../..../..../etc/hostname http://localhost:8888/..../..../..../..../..../..../etc/host... mypc These regex substitutions are so easy to bypass :)
- hackideiomat 3y agoAlways fun :D
- x-complexity 3y agoAll this tells me is that preventing directory traversals can only be done by checking absolute file paths are within a bounded range, and nothing else.
- nonameiguess 3y agoRunning the server as a service account that can only read its own directories, running it in a chroot, running it in a mount and pid namespace, using SELinux to further restrict what files it can read even in principle. Of course, if you're trying to go superminimal anyway, it's not that big a deal to create a server that doesn't even have sensitive data on it. You can make init simply mount a root filesystem that only has busybox and whatever files you want to serve and starts up the httpd process and nothing else. Turn Linux into a unikernel basically. If you compile busybox yourself, you're also able to remove all the subcommands you don't actually need.
- pmarreck 3y agochange that to: > gsub(/\/\.\.+\/?/, "/", request_filename) # avoid directory traversal source: am "regex expert" >..< (and know how to spell)
- hackideiomat 3y agoU sure? echo -e "GET /../.. HTTP/1.0\r\n\r\n" | nc localhost 8888
- pmarreck 3y agoHah. I know the web frameworks have solved this issue but it seems like a fun puzzle to figure out without peeking